Hopper logo
Hopper

Hopper is an accredited, mobile-only travel agency using big data to analyze and predict airfare and accommodations. A fully remote employer, Hopper strives to

Senior Security Engineer

Location

Spain

Posted

10 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudGoogle Cloud PlatformSDLC

Job Description

Senior Security Engineer

Hopper

• Own and evolve our vulnerability management program with a focus on application security — container images, dependencies, code scanning, and runtime detection • Build and maintain security tooling that integrates directly into CI/CD pipelines and developer workflows, so security happens automatically rather than as a gate • Use AI extensively to write code faster, automate analyses that would otherwise require manual review, and build intelligent tooling that scales beyond what a small team could achieve manually • Assess and improve how we leverage available telemetry across our systems • Work directly with engineering teams to influence secure development practices — not by writing standards and documents, but by shipping tools and defaults that make the secure path the easy path • Investigate and respond to security findings when needed, but spend more of your time building systems that prevent and detect issues than manually chasing them • Adapt quickly as priorities shift — our team is agile and tomorrow's challenge may look different from today's

Job Requirements

  • At least 5 years experience software and/or platform engineering, with the ability to design, build, and maintain production-quality tools
  • Deep experience in application security and vulnerability management — you understand CVEs, dependency risks, container security, and SDLC integration, and you have opinions about what's worth fixing and what's noise
  • Hands-on experience with cloud infrastructure, ideally GCP/GKE or equivalent, with the ability to adapt to our stack
  • A demonstrated habit of using AI tools — coding assistants, LLMs — as a core part of how you build and analyse, not an occasional shortcut
  • A bias toward automation — when you see a repetitive manual task, your instinct is to write a tool, not a runbook
  • Comfort with ambiguity and ownership — you'll often be the only person on a problem and will need to make judgment calls on priority, approach, and scope without waiting for direction
  • Experience influencing engineering culture around security, knowing how to make developers care without slowing them down
  • Strong written and verbal communication skills, including the ability to articulate our security posture clearly to customers when needed.

Benefits

  • Well-funded and proven startup with large ambitions, competitive salary, upsides of pre-IPO equity packages.
  • Hopper covers the cost of employee premiums for private medical and dental coverage.
  • Hopper also offers private life and accident coverage.
  • Please ask us about our very generous parental leave, much above industry standards!.
  • Access to co-working space on demand through FlexDesk AND Work-from-home stipend.
  • Unlimited PTO.
  • Hopper offers a monthly cash allowances for gym memberships and to cover home office expenses for a comfortable remote working experience.
  • Carrot Cash travel stipend.
  • Entrepreneurial culture where pushing limits and taking risks is everyday business.
  • Open communication with management and company leadership.
  • Small, dynamic teams = massive impact.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200Since 2018H1B Sponsor

• Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others). • Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems. • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries. • Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication. • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers. • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy. • Able to participate in on-call rotation.

United States
$225K - $275K / year
Immersive Labs logo

Cyber Security Engineer – Red Team

Immersive Labs

The leader in people-centric cyber resilience.

Full TimeRemoteTeam 201-500Since 2017H1B No Sponsor

• Utilising knowledge of pen test and red teaming engagements and techniques to plan, write and improve offensive security labs, challenges and online learning content on the Immersive One platform. • Produce multi-format content utilising various teaching methods; practical exercises, questions & gamification • Test Red Team labs and ranges to ensure they function as expected • Research vulnerabilities, tools and offensive tactics and compile this research to deliver practical and theory labs to users • Compile technical research into understandable concise content for both technical and non-technical audience • Work with the wider Product team on new projects and product innovations and how best to deploy them

United Kingdom

Role Description Sigma Defense is seeking a Cybersecurity Lead Engineer to support an enterprise DevSecOps platform. - Support DevSecOps and Software Engineers in developing secure platforms and effectively communicating regarding the risk posture of the platforms. - Support of full RMF lifecycle for authorization and re-authorization of existing and novel capabilities including regular communication with stakeholders and authorizing personnel. - Identification and reduction of system vulnerabilities to achieve compliance objectives. - Mentorship and proliferation of cybersecurity culture within team. Qualifications - 8-10 years of Cybersecurity experience. - Experience with DoW RMF policy. - Experience maintaining cybersecurity on an enterprise DevSecOps platform. - Registered DoW RMF Practitioner (RDRP) is preferred. - Must be a U.S. citizen. Requirements - Mandatory Certifications: CISSP - Personnel Clearance Level: Candidate must possess or have the ability to obtain an active Secret security clearance or higher. Clearance may be sponsored for the right candidate. - Education Requirements: Bachelor's degree from an accredited college or university in Cyber Security, Information Technology, Information Systems, Computer Science, Computer Engineering, Mathematics, or related field of study. Degree may be substituted for comparable additional industry experience and/or industry accepted training and certification. Benefits - Salary Range: $135,000 - $145,000 annually. - Dental and Vision Insurance - Medical Insurance to Include HSA, FSA, and DFSA Plans - Life and AD&D coverage - Employee Assistance Program (EAP) - 401(k) Plan with Company Matching Contributions - 160 Hours of Paid Time Off (PTO) - 12 (Floating) Holidays - Educational Assistance - Highly Competitive Salary

United States
$135K - $145K / year
Job Closed
Full TimeRemoteTeam 10,001+Since 1856H1B Sponsor

• We are seeking a highly motivated Senior Security Engineer with a strong passion for Identity and Access Management (IAM) to join our Enterprise Security & Infrastructure (ESI) organization. • The ideal candidate brings hands-on experience designing, engineering, implementing, and supporting enterprise-scale identity solutions across hybrid environments (on-premises and cloud). • This role requires a deep understanding of modern identity technologies, along with the ability to secure and optimize identity platforms that support critical business operations. • A successful engineer in this role will maintain awareness of new security and identity trends, research, evaluate, design, and recommend technical security solutions for the enterprise. • This role is critical in ensuring the secure, efficient, and compliant management of identities and access across the organization, helping to protect enterprise assets while enabling business productivity. • The Senior Security Engineer, Identity & Access Management is responsible for designing, implementing, and maintaining secure, scalable IAM solutions across hybrid environments, while driving modernization toward Zero Trust and cloud-based identity models. • This role focuses on engineering automated identity processes, strengthening access governance and privileged access controls, and integrating AI-enabled capabilities to enhance security and operational efficiency. • The engineer partners closely with cross-functional teams to assess and mitigate identity-related risks, implements monitoring and automated response for identity threats, and contributes to technology evaluation and innovation. • Additionally, the role ensures compliance with regulatory requirements, supports audit readiness, and establishes standards and best practices to continuously improve enterprise identity security.

California + 2 moreAll locations: California | Oregon | Washington
$5.7K - $10.9K / year